# Script field and regexp

**URL:** <https://discuss.elastic.co/t/script-field-and-regexp/80505>\
**Category:** Kibana\
**Created:** [March 29, 2017, 3:08pm UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505 "2017-03-29T15:08:09Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![apoc](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@apoc](https://discuss.elastic.co/u/apoc)\
**Post date:** [March 29, 2017, 3:08pm UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/1 "2017-03-29T15:08:10Z")

</div>

Hello,

I installed the elastic stack 5.2.2.  
In a script field, I would like to test another field with a regexp :  
`return (doc['processContext.componentName'].value ==~ /IN/);`

I get an error _Courier Fetch: 1 of 5 shards failed._ in kibana. Nothing in elasticsearch or kibana logs

The _script.painless.regex.enabled_ parameter is set in _elasticsearch.yml_

Any clue ?

Thank you for your help

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [March 29, 2017, 4:14pm UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/2 "2017-03-29T16:14:57Z")

</div>

can you try with something like if (doc['....'].value ==~ /IN/) return 'match'; else return ''; ?

---

<div class="post-metadata">

**Author:** ![apoc](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@apoc](https://discuss.elastic.co/u/apoc)\
**Post date:** [March 29, 2017, 4:34pm UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/3 "2017-03-29T16:34:21Z")

</div>

Same error 😥

---

<div class="post-metadata">

**Author:** ![mfillion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mfillion/32/16893_2.png) [@mfillion](https://discuss.elastic.co/u/mfillion)\
**Post date:** [March 30, 2017, 7:42am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/4 "2017-03-30T07:42:12Z")

</div>

I try other things :

## Test 1 (Kibana script field):

return [  
"doc['processContext.componentName'] = " + doc['processContext.componentName'],  
"doc['processContext.componentName'].value = " + doc['processContext.componentName'].value,  
"doc['processContext.componentName'].length = " + doc['processContext.componentName'].length,  
""TOTO" ==~ /IN/ = " + ("TOTO" ==~ /IN/),  
""IN\_TOTO" ==~ /IN/ = " + ("IN\_TOTO" ==~ /IN.\*/)  
];

**Works with this result :**  
doc['processContext.componentName'] = [IN\_Ret], doc['processContext.componentName'].value = IN\_Ret, doc['processContext.componentName'].length = 1, "TOTO" ==~ /IN/ = false, "IN\_TOTO" ==~ /IN/ = true

## Test 2 (Kibana script field):

return [  
"doc['processContext.componentName'] = " + doc['processContext.componentName'],  
"doc['processContext.componentName'].value = " + doc['processContext.componentName'].value,  
"doc['processContext.componentName'].length = " + doc['processContext.componentName'].length,  
""TOTO" ==~ /IN/ = " + ("TOTO" ==~ /IN/),  
""IN\_TOTO" ==~ /IN/ = " + ("IN\_TOTO" ==~ /IN._/),  
"doc['processContext.componentName'].value ==~ /IN/ = " + (\*\*doc['processContext.componentName'].value ==~ /IN._/\*\*)  
];

**Don't work** , same Kibana error " **Courier Fetch: 1 of 5 shards failed**". Nothing in elasticsearch or kibana logs

## Test 3 (Kibana Dev Console):

GET test-_/\_search  
{  
"query": {  
"match\_all": {}  
},  
"script\_fields" : {  
"test1" : {  
"script" : {  
"lang": "painless",  
"inline": "return \*\*doc['processContext.componentName'].value ==~ /IN._/\*\*"  
} } }}

**Works with this result :**  
{  
"took": 5,  
"timed\_out": false,  
"\_shards": {  
"total": 5,  
"successful": 5,  
"failed": 0  
},  
"hits": {  
"total": 998,  
"max\_score": 1,  
"hits": [  
{  
"\_index": "test-2017-03",  
"\_type": "step",  
"\_id": "AVsVAHiaaDmnhEi3LNvC",  
"\_score": 1,  
"fields": {  
"test1": [  
false  
] } }, ....

## Test 4 (Add the script fields in a saved search):

Trying to add the script fields directly in the kibanaSavedObjectMeta.searchSourceJSON of a saved search

**Don't work** when we try to open this search in kibana. Same Kibana error " **Courier Fetch: 1 of 5 shards failed**". Nothing in elasticsearch or kibana logs

Thank you for your help,

---

<div class="post-metadata">

**Author:** ![mfillion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mfillion/32/16893_2.png) [@mfillion](https://discuss.elastic.co/u/mfillion)\
**Post date:** [April 4, 2017, 7:59am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/5 "2017-04-04T07:59:33Z")

</div>

I've created an issue : [https://github.com/elastic/kibana/issues/11016](https://github.com/elastic/kibana/issues/11016)

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 4, 2017, 8:24am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/6 "2017-04-04T08:24:46Z")

</div>

Hi @mfillion,

what is the type of the field `processContext.componentName` in the mapping? Is the type consistent across all indices matching the index pattern used?

---

<div class="post-metadata">

**Author:** ![mfillion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mfillion/32/16893_2.png) [@mfillion](https://discuss.elastic.co/u/mfillion)\
**Post date:** [April 4, 2017, 9:09am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/7 "2017-04-04T09:09:26Z")

</div>

Hi, the field is mapped like this :

"componentName": {  
"type": "keyword",  
"ignore\_above": 5000  
}

Yes, the type is consistent across all indices.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 4, 2017, 9:37am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/8 "2017-04-04T09:37:08Z")

</div>

Is `processContext` of type `object` (default if no `type` is set) or `nested`?

Also, does the full `processContext.componentName` field exist in all documents? The presence of `ignore_above` indicates this might not be the case. Otherwise the script might have to contain a guard against that.

---

<div class="post-metadata">

**Author:** ![mfillion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mfillion/32/16893_2.png) [@mfillion](https://discuss.elastic.co/u/mfillion)\
**Post date:** [April 4, 2017, 9:57am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/9 "2017-04-04T09:57:58Z")

</div>

processContext is of type object.

The processContext.componentName is in all documents. I've tried to put a guard based on a doc.contain... but the error was the same.

If you watch my case 3, it works in dev console. I don't understand why here and not in the script field...

Thanks for your help,

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [April 4, 2017, 10:01am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/10 "2017-04-04T10:01:43Z")

</div>

Thank you for trying that out. This is a curious problem indeed. Maybe you can inspect the network traffic using the browser developer tools, take the query that the Discover app sends and execute it in the dev console? That way we could try to reduce the query to a minimal failing example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2017, 10:01am UTC](https://discuss.elastic.co/t/script-field-and-regexp/80505/11 "2017-05-02T10:01:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
